Re: Suggestion to improve CAPEC 37

2023-03-03 Thread Rich Piazza
Problems for a Safer World™ From: Nan MESSE Date: Friday, March 3, 2023 at 10:23 AM To: CAPEC Researcher Discussion Cc: Avi Shaked Subject: Suggestion to improve CAPEC 37 Dear CAPEC community, We have realized that CAPEC-37 can also be related with CWE-284. Having improper access control can lead to

Suggestion to improve CAPEC 37

2023-03-03 Thread Nan MESSE
Dear CAPEC community, We have realized that CAPEC-37 can also be related with CWE-284. Having improper access control can lead to the disclosure of sensitive data embedded within the system (For example, sensitive files, certificates and tokens, etc.). What do you think about it ? Best rega